Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 186

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Bernie Sanders and Ron DeSantis speak out against data center boom. It's a bad sign for AI industry
Best credit cards to help you meet your New Year’s resolutions
Chip stocks rally to start 2026 after third-straight winning year
Anthropic's 'do more with less' bet has kept it at the AI frontier, co-founder Amodei tells CNBC
'Queen City' Charlotte was the king of the stock market in 2025
These are the most overbought and oversold stocks in the S&P 500 as 2026 begins
South Korea's Lee begins China state visit after North fires missiles
Maduro is out but his top allies still hold power in Venezuela
Bank of America expects a boost in dividends in 2026. These stocks have payouts that beat the market
Maduro overthrow in oil-rich Venezuela unlikely to shake energy markets in the near term